This is a deterministic synthetic illustration. Every chart, outcome count and group row is filtered to the selected reporting period. There are 2,041 evaluated prompts and 132 observations without an applicable policy. The intervention percentage uses all observed prompts as its denominator. No Policy is neither evaluated nor compliant; policy-category counts exclude it. No outcome establishes compliance, complete coverage or a completed audit record.
Synthetic reconstruction, not a customer report. No report is saved, scheduled or exported from Aona.
Scope to confirmReports reflect selected collection scope. They contribute evidence; they do not establish compliance.
Coverage and deployment details
A report supports an internal review. It does not prove compliance, regulator acceptance or a complete audit record.
Report scope depends on collection coverage, period and filters. Confirm the fields and PDF output for your deployment.
The example is a separate synthetic report, not a captured Aona export or customer result.
Built for your decision
Turn an AI report into a decision.
Choose the review you need to prepare: a stakeholder report, an outcome investigation or an audit discussion.
CISOs and security managers
Review AI policy violations with supporting context
Stakeholders need to understand blocked, redacted and warned interactions.
Synthetic review report
Scope and outcomes
2012 compliant4 redacted3 blocked1 warned
Scope graphic20 evaluated · synthetic
Review note
Read the period and collection scope with the outcome.
Keep in viewOutcome counts alone do not establish that risk has fallen.
Scenario details
Inspect
Policy outcomes
Reporting period
Supporting context
Next decision
Choose which rule or workflow needs investigation.
Look at the reporting period, evaluated activity and outcomes together. Redacted, blocked and warned interactions describe different events. A total can help you identify a pattern, but it does not by itself show whether the policy is correctly scoped or whether organisational risk has fallen.
GRC and compliance teams
Prepare evidence for an internal AI control review
An internal control review needs evidence of employee AI controls.
Synthetic review report
Evidence set
Review focusReview focus
Review focus
Pair the report with the applicable policy and records.
Keep in viewA report contributes evidence; it does not establish compliance.
Scenario details
Inspect
Report scope
Applicable policies
Supporting records
Next decision
Identify evidence gaps and questions for the accountable reviewer.
Use the report alongside the applicable policies and supporting records. Confirm what was collected, which controls were evaluated and what remains outside coverage. The report can contribute to a reviewer’s evidence set; it does not certify compliance or guarantee acceptance by an auditor or regulator.
IT and business stakeholders
Share an AI security report that leads to a decision
Business stakeholders need a report they can discuss and act on.
Synthetic review report
Decision handoff
Next stepNext step
Next step
Assign a follow-up to the observation.
Keep in viewConfirm the report scope and PDF output needed for your review.
Scenario details
Inspect
Selected components
Reporting period
Print to PDF
Next decision
Agree who owns each follow-up and when to review it.
Choose the report components and period that fit the audience. Share the report as a PDF and agree who owns each follow-up. A decision about training, a guardrail or a workflow should be traceable to the observation that prompted it.
From evidence to a decision
What should an AI security report tell your stakeholders?
An employee AI security report should explain the finding, the evidence behind it and the question still open. Pair the report with a short review brief so a CISO, GRC lead or IT owner knows what to do next.
AI security review briefIllustrative worksheet
Finance + Operations
11 Aug–9 Sep 2026 · 20 evaluated prompts
12 compliant
4 redacted
3 blocked
1 warned
Observation to review
3 blocked interactions
An observed outcome, not a risk-reduction score or proof of compliance.
Synthetic supporting recordBlocked interaction
Open question
Was the intended rule applied to the intended workflow?
Next step
Inspect a supporting record and validate the assigned control
Suggested owner
Security + IT / endpoint administrator
A suggested companion to your report. Not a saved Aona task or customer review.
Report walkthrough
Reduced motion · choose a step
What to include in an internal AI control review
Use the configured report and its Print to PDF output alongside the applicable policy, supporting records and an explicit list of gaps. The example above reuses the report’s 20 synthetic outcomes: 12 compliant, four redacted, three blocked and one warned.
Keep observations without an applicable policy separate from compliant outcomes. The report can contribute to an internal review; it does not certify compliance or guarantee an auditor’s acceptance. Confirm the actual report components and available evidence during the demo.
Put the period, covered people and evaluated activity next to the finding. Supporting evidence includes the relevant rule, available event context and collection scope. Keep collection gaps visible. A blocked count alone does not establish policy effectiveness.
Agree the decision, responsible owner and next review date outside this illustrative worksheet. Use the available records to resolve the open question before changing a rule or expanding a control.
Bring a reporting question and the audience who needs to act on it.
Selected collection, not every employee AI interaction.
01 / 03
Security & ComplianceIllustrative example
Security & Compliance · Synthetic example
20evaluated prompts Synthetic example
Compliant
12
Redacted
4
Blocked
3
Warned
1
No Policy is a separate state, not a compliant outcome.
No Policy does not mean compliant.
02 / 03
Report canvas + stakeholdersIllustrative example
Report canvas · Print to PDF
Employee AI security review
Reporting period & scope
Selected policy outcomes
Supporting context
Evidence, not a compliance certification.
03 / 03
Workflow details
01 / Global admin · Reports
Choose the report scope
Define the reporting question, period and relevant components. Keep the covered population visible so stakeholders know which employee activity the report represents.
02 / Security & Compliance
Read the outcome correctly
Separate evaluated activity from observations without a policy. No Policy does not mean compliant. Check the underlying record when a figure needs explanation.
03 / Report canvas · Print to PDF
Share and assign follow-up
Share the configured report and make its limits explicit. Agree on the person who will investigate the open question and when the team will review the evidence again.
Make the demo useful
What to ask when evaluating AI security reporting software
Start with the report you need to present and the decision it should support. Use a synthetic example to verify how scope and outcomes carry through the review.
Bring to the conversation
01Your reporting audience
02One finding to inspect
03The collection scope
01Reporting scopeWhich activity is absent from this report?
What to inspect
Time period, covered users and included components.
02Outcome definitionsDo these totals use the same denominator?
What to inspect
Evaluated, compliant, redacted, blocked, warned and no-policy states.
03Supporting evidenceCan a reviewer understand why this outcome occurred?
What to inspect
Available event context and the relevant rule.
04Sharing and follow-upWhat decision and owner will accompany the report?
What to inspect
The configured report and Print to PDF view.
Review the reporting scope, policy outcomes and PDF your stakeholders need.
In your cloud, on your premises or on Aona-managed servers. Choose backend hosting separately from where Aona processes prompts, then agree operating responsibilities, storage, retention and supported integrations.
Yes. Aona prompt-processing options are the user device/on-edge, customer cloud or on-premises, and Aona-managed servers. Confirm the supported configuration, controls, file paths and telemetry for your rollout; the options do not imply identical capabilities or that all existing clients already use on-edge processing. The destination AI provider's data handling remains separate.
Include the period, collection scope, observed activity, evaluated policy outcomes and relevant supporting context. Explain material gaps and record the questions that need follow-up. Do not present an activity count as a complete measure of organisational risk.
No. No Policy indicates that the observation was not evaluated by an applicable policy. It must not be grouped with compliant outcomes or presented as approval to use that tool or workflow.
The current global-admin report view has a Print to PDF action. Confirm the report components and print output you need during evaluation. The printable example on this page is a synthetic website illustration, not an export from a customer account.
Review the available event identity, time, AI tool, applicable policy and outcome alongside collection coverage and the reporting period. Confirm which fields are available on the selected path. An observed event is not a complete record of every employee AI interaction, and the public events API excludes compliant records.
Observed employee AI activity and policy outcomes within the selected reporting scope. The demo confirms the available fields, filters and underlying records.
The public events API excludes compliant records, while a configured report can include them. Different periods, filters and collection scopes also affect totals. Match those definitions before attempting to reconcile a report with an API response.
No. It supports your review; compliance conclusions depend on your obligations, evidence and accountable reviewers.
The report reflects its collection coverage, selected period and filters. Those boundaries should accompany any conclusions.
Your use case. Your demo.
Build the AI security review your team needs.
Bring the questions your stakeholders ask. We’ll focus on the reporting view, supporting records and output your team needs to share.